Sceawere
Vulnerability Detail
CVE-2026-108865UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
AmoyLab Unla OAuth2 Authentication Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 3h ago
- Vendor
- AmoyLab
- Product
- Unla
- Attack Type
- Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
AmoyLab Unla through 0.10.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid access tokens because the OAuth2 server never authenticates a resource owner. Attackers can register a client, request a code from /authorize, and exchange it at /token to access OAuth2-protected MCP prefixes, proxied upstream APIs and injected credentials.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-10-11T14:17:06.640Z",
"pubdate": "2026-10-11T14:17:06.640Z",
"executiveSummary": "AmoyLab Unla versions through 0.10.0 are susceptible to an authentication bypass vulnerability stemming from a critical design flaw in the OAuth2 implementation.\nThe vulnerability exists because the OAuth2 server fails to perform resource owner authentication during the authorization flow, allowing unauthenticated remote attackers to generate valid access tokens.\nBy successfully exploiting this flaw, an attacker gains unauthorized access to protected MCP prefixes, proxied upstream APIs, and sensitive injected credentials.\nThis vulnerability presents a high-risk scenario, as it completely subverts the security boundary intended by the OAuth2 protocol.\nExploitation requires no prior authentication or administrative privileges, as the system incorrectly assumes the validity of any client registration request.\nThe impact includes full unauthorized access to sensitive service integrations and potential compromise of backend systems relying on the OAuth2-protected gateway.\nThis issue represents a total failure of identity verification mechanisms within the authentication provider.",
"technicalDetails": "The root cause of this vulnerability lies in the fundamental failure of the AmoyLab Unla OAuth2 authorization server to enforce the authentication of the resource owner (user) before granting access codes.\nIn a standard OAuth2 workflow, the /authorize endpoint is intended to challenge the resource owner to authenticate, thereby validating their identity before granting an authorization code.\nIn the affected Unla implementation, the authorization logic bypasses these identity verification steps entirely, effectively transforming the authorization process into an automated, permissionless grant system.\nThe attack flow begins when an attacker performs a standard client registration with the Unla service. Once registered, the attacker invokes the /authorize endpoint. Because the server does not verify the resource owner's identity, it immediately issues a valid authorization code to the attacker.\nFollowing the receipt of this code, the attacker proceeds to the /token endpoint, where the authorization code is exchanged for a legitimate, signed access token.\nBecause the server considers this token valid, the attacker can subsequently use it to perform unauthorized requests against protected resources. This includes, but is not limited to, accessing sensitive MCP (Model Context Protocol) prefixes and interacting with proxied upstream APIs.\nFurthermore, since the application injects credentials into these proxied streams, an attacker who successfully acquires an access token can intercept or utilize these injected credentials to escalate access into underlying backend infrastructure.\nThis vulnerability is classified as an authentication bypass that operates at the protocol level. It does not require specialized knowledge of the target's internal state beyond understanding the standard OAuth2 interaction flow.\nThe vulnerability affects all versions of AmoyLab Unla through 0.10.0. The lack of an authentication gate at the /authorize endpoint ensures that any entity capable of communicating with the Unla service can obtain high-privilege access tokens without proving their identity."
}